Skip to content
Content type · 2,018 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 2,018 sort newestlargest fineoldest
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Sep 30, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers Supervisory Authorities Sep 30, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€35,000 E-Power S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 35,000 on E-Power S.r.l. The controller engaged in direct marketing activities in a way that violated general data processing principles. ITALY ·Garante ·Art. 5, 6, 7 +5 Direct Marketing Controllers Marketing Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Sep 25, 2025
€840 SERVACE S.L.: Violation of the general principles for data processing. ⇄ Een boete van 840 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 6 Controllers Processing Accountability Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 13 Controllers Processing Consent Sep 25, 2025
€32,000 Autonomous Province of Bolzano: Non-compliance with general principles of data processing. ⇄ Een boete van 32.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +4 Controllers Processing Supervisory Authorities Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€3,000 Municipality of Isola del Gran Sasso: Insufficient legal basis for data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 +2 Public Authority Criminal Data Controllers Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient compliance with data subject rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Right of Access Personal Data Controllers Sep 25, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€3,960 Comune di Pazzano: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 3,960 on the Commune di Pazzano. The controller failed to comply with a order of the DPA. ITALY ·Garante ·Art. 12, 13, 58 Supervision Supervisory Authorities Controllers Sep 25, 2025
€3,960 Municipality of Pazzano: Insufficient cooperation with the supervisory authority. ⇄ Een boete van €3.960 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 13, 58 Controllers Supervisory Authorities Supervision Sep 25, 2025
€32,000 Provincia Autonoma di Bolzano: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 32,000 on the Provincia Autonoma di Bolzan. The controller implemented video surveillance with automated licence plate recognition… ITALY ·Garante ·Art. 5, 6, 12 +4 Controllers Monitoring Supervisory Authorities Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for the processing of personal data. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Processing Controllers Sep 25, 2025
€840 SERVACE S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 840 on SERVACE S.L. The controller used its employees' private email addresses for internal communication. The original fine of EUR 1,400… SPAIN ·AEPD ·Art. 5, 6 Controllers Processing IP Address Sep 25, 2025
€600 Property manager: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 600 on a porperty manager. The controller operated a website for owners and tenants that did not implement adequate technical and… SPAIN ·AEPD ·Art. 32 Security Controllers Processing Agreement Sep 23, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Violation of the general principles of data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Controllers Processing Security Sep 22, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on DHL PARCEL IBERIA, S.L. The conroller printed the private phone number of the recipient on a parcel, making it visible to third… SPAIN ·AEPD ·Art. 32 Controllers Recipient IP Address Sep 22, 2025
€1,000 Dr. Max SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dr. Max SRL. The controller failed to comply with a data subject's request to delete their personal data. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Sep 18, 2025
€100,000 SAMARITAINE SAS: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 33, 38 Controllers Processing Security Sep 18, 2025
€1,000 Dr. Max SRL: Insufficient compliance with data subjects' rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Processing Supervisory Authorities Sep 18, 2025
€100,000 SAMARITAINE SAS: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 100,000 on SAMARITAINE SAS. After multiple theft incidents, the controller installed security cameras disguised as smoke detectors to… FRANCE ·CNIL ·Art. 5, 33, 38 Data Breaches Controllers Supervisory Authorities Sep 18, 2025
€150,000 DIGI SPAIN TELECOM, S.L.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 150,000 on Digi Spain Telecom S.L.U. The controller rejected the application for a contract due to outstanding debt, despite this being… AEPD ·Art. 6 ·Insufficient legal basis for data processing Controllers Telecommunications Processing Agreement Sep 17, 2025
€150,000 DIGI SPAIN TELECOM, S.L.U.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 150.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Controllers Sep 17, 2025
€1.5M CARREFOUR FINANCIAL SERVICES, E.F.C.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.500.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Sep 17, 2025
€1.5M SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Agreement Sep 17, 2025
€2,670 POLAND DPA: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 2,670 on an unkonwn company in the health care sector. The controller appointed its CEO as the DPO. UODO ·Art. 38 ·Lack of appointment of data protection officer Supervisory Authorities Controllers Personal Data Sep 12, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Buccino. The controller published pictures of minors and people with mental health conditions in multiple… ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Supervisory Authorities Sep 11, 2025
€6,000 Company: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on a company. The controller used video surveillance at its sites, but did not display adequate signs to inform data subjects about… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Sep 11, 2025
€1,000 Giada FM S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Giada FM S.r.l. The controller failed to provide an employee with requested certificates. ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Supervisory Authorities Sep 11, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing. ⇄ Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Processing Sep 11, 2025
€1,000 Giada FM S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 12, 15 Right of Access Controllers Personal Data Sep 11, 2025
€8,000 Migliarino San Rossore Massaciuccoli Regional Park Authority: Insufficient legal basis for the processing of data. ⇄ 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 20 Controllers Processing Accountability Sep 11, 2025
€12,000 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Minstry of the Interior. During the Covid-19 pandemic, the controller published a list of employees' with names and… ITALY ·Garante ·Art. 5, 6, 9 Controllers Processing Education Sep 11, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Sep 11, 2025
€8,000 Migliarino San Rossore Massaciuccoli Regional Park Authority: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 8,000 on Migliarino San Rossore Massaciuccoli Regional Park Authority. The controller published personal data of a job applicant on its… ITALY ·Garante ·Art. 5, 6, 20 Personal Data Controllers Processing Sep 11, 2025
€18,000 Comune di Nichelino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 18,000 on the Comune di Nichelino. The controller published the sensitive personal data of a former employee, including the decision to… ITALY ·Garante ·Art. 5, 6, 12 +1 Personal Data Types of Special Categories of Personal Data Controllers Sep 11, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Sep 11, 2025
€18,000 Municipality of Nichelino: Insufficient legal basis for data processing. ⇄ Een boete van 18.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +1 Controllers Processing Public Authority Sep 11, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 9, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Unita Turism Holding S.A. The controller did not implement adequate technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 9, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Processing Agreement Sep 8, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Sep 5, 2025
€3M Allium UPI: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000.000 euro - De Estische Autoriteit voor Gegevensbescherming (AKI). ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Minors Sep 5, 2025